2037 4 HITRUST Feature Graphic
img

Stay in the know

Get the latest insights delivered right to your inbox.

Privacy Notice

Trust is both difficult to earn and yet, it can be quickly lost. But it’s always worth reinforcing—especially when it comes to healthcare and technology.

Trust is the cement that helped build the foundation for the Surescripts network and supports every Surescripts Network Alliance® participant. It also enabled 27.2 billion exchanges of patient clinical and benefit information and safely connected 2.29 million healthcare professionals and organizations to the network for access to clinical and benefit information for virtually every insured American in 2024.

Why It Matters

Health intelligence sharing is a critical element that enables care providers and healthcare organizations to deliver safe, quality and affordable care to patients.

But to share healthcare data for the benefit of patients, organizations must ensure that it will be kept secure and out of the hands of bad actors – a challenge that proves more difficult each year.

State of Play

In 2024, health data breaches impacted 53% of the U.S. population, making it the worst year on record in scope of breaches. According to one report, over 185 million individual records were exposed in 2024.

As a result, organizations like Surescripts are continually enforcing rigorous privacy, security and network access standards for our network and on behalf of all participants in the Network Alliance, aiding cyber resilience and protecting health information from every angle.

The News

As part of the ongoing commitment to network integrity and security compliance, Surescripts technology and data infrastructure systems recently achieved HITRUST r2 Certification by HITRUST for information security.

HITRUST r2 Certification demonstrates that Surescripts’ technology and data infrastructure has met demanding regulatory compliance and industry-defined requirements and is appropriately managing risk. This achievement places Surescripts in an elite group of organizations worldwide that have earned this certification.

The platforms that achieved HITRUST r2 Certification include, but are not limited to:

  • Clinical Direct Messaging
  • Directories/Directory Manager
  • E-Prescribing
  • Electronic Prescribing of Controlled Substances
  • Electronic Prior Authorization
  • Eligibility & Formulary
  • MPI - Master Patient Index
  • Med History for Populations
  • Med History: Ambulatory and Reconciliation
  • Patient Medication Benefit Check (PMBC)
  • Provider Portal
  • Real-Time Prescription Benefit
  • Record Locator & Exchange
  • Specialty Patient Enrollment
  • Supporting Application Infrastructure
  • Surescripts Health Information Network Interconnect
  • Workbench

Zoom In

The HITRUST r2 assessment is a two-year certification which provides the highest level of assurance focused on a comprehensive specification of controls based on data volumes, regulatory compliance, and other risk factors.

By including federal and state regulations, standards, and frameworks and incorporating a risk-based approach, the HITRUST Assurance Program helps organizations address security and data protection challenges through a comprehensive and flexible framework of prescriptive and scalable security controls.

Zoom Out

Data protection and information security are critical to advancing health intelligence sharing and innovative technology that provide clinicians and healthcare professionals with timely access to the clinical and benefit information they need to help address some of the biggest challenges facing healthcare today.

What They Are Saying:

Jeremy Huval, Chief Innovation Officer at HITRUST, said, “HITRUST certification is globally recognized as validation that information security and privacy controls are effective and compliant with various regulations. HITRUST certification is considered the gold standard because of the comprehensiveness and applicability of the control requirements, depth of the assurance process, and level of oversight that ensures accuracy.”

Learn more about Surescripts’ commitment to rigorous standards for data security across the network.

You may also like